Apple macOS Full Disk Access AI Agents: What to Check Now
Apple confirmed this week that it's tightening macOS Full Disk Access controls, requiring a "very explicit user action" before any Mac app can receive the permission. The company says autonomous AI agents have pushed the risk of that access high enough to justify the change, according to TechCrunch.
Full Disk Access already lets an approved app read files, mail, messages, and browsing history on a Mac. Apple itself says some developers have used that access in ways users don't fully understand, according to Ars Technica.
Nothing about the new approval step has shipped yet. That means the practical move for Mac owners, especially anyone running a desktop AI assistant, is reviewing what's already been granted rather than waiting for Apple to finish building the feature.
What Apple's macOS Full Disk Access controls mean for AI agents
Apple's developer blog draws a clear line around intent. Users who "genuinely wish to grant an app this extraordinary level of access" will need a more deliberate step to do so, the company wrote, according to TechCrunch.
That's the full extent of the confirmed change. TechCrunch's report includes no release version, no beta timeline, and no description of what the new consent screen will look like. Nothing in the available reporting says whether apps that already hold Full Disk Access will be asked to re-confirm it later, and Apple didn't respond to TechCrunch's questions about implementation this week.
Full Disk Access wasn't built with AI agents in mind. Apple designed the permission so legitimate cross-system tools, like backup software, could reach protected folders, TechCrunch reported. Apple has not said the permission itself is defective; it says the risks have increased as AI agents become more capable and autonomous.
Why AI agents changed Apple's calculus on an old permission
Apple's stated reason for acting is direct. As AI agents gain capability and operate with less human oversight, the risk tied to broad file access "will grow substantially," the company wrote, adding that it wants users to understand that risk before granting it, according to Ars Technica.
A recent incident involving Meta's Muse shows why that risk feels concrete. Columnist Jason Aten reported that Muse sent him an unsolicited notification referencing a private Messages thread with a co-worker, something he said he never gave the app permission to read, roughly two weeks before Apple's announcement, according to Ars Technica.
Muse's developer disputed that account. Reading Messages inside Muse requires two separate approvals, the company told Ars Technica: macOS Full Disk Access at the system level, plus a Messages connector a user has to switch on inside the app itself.
Security researcher Patrick Wardle questioned whether that distinction holds up technically. He argued that once an app has Full Disk Access, "any (non-root) file is readable, browsing history, browser cookies, chats, etc," according to Ars Technica. That's Wardle's technical objection to the developer's framing, not confirmation of what Muse actually did with Aten's messages; Ars Technica's reporting doesn't resolve which account is correct.
Wardle had already raised a separate, more concrete concern 11 days before Apple's announcement. He disclosed a Muse configuration that let other local code, including commands injected through ClickFix-style attacks, take control of the assistant and reach whatever Muse itself could already access, Ars Technica reported.
Taken together, these reports don't show Apple's permission being secretly expanded. They show access a user already approved turning into a bigger liability once the app managing it is compromised, misconfigured, or more autonomous than the person who granted it expected.
What the Claude Desktop case does, and doesn't, prove
A separate disclosure adds a concrete technical example of that same pattern. A researcher published a writeup showing that Claude Desktop, tested at version 1.1.673, could be manipulated by an attacker with local code execution into reading, writing, and listing files inside folders a user had specifically granted Claude access to during normal agent sessions, according to 0day.gg.
The technique didn't require stealing new permissions. By launching Claude with Chromium's remote debugging enabled, then quietly creating and archiving a hidden session scoped to a folder the user had already approved, an attacker could inherit Claude's existing access without it appearing anywhere in the app's interface, per the researcher's writeup.
The researcher's own report lists the issue as fixed in version 1.1.2321, a status that comes from the researcher, not from an independent statement by Anthropic. That timeline is also odd on its face: Anthropic had closed the original HackerOne report as "Informative/WontFix" the day before the researcher disclosed it publicly, according to 0day.gg.
Anyone running Claude Desktop should check whether the installed version is 1.1.2321 or later, treating that number as the researcher's account of a fix rather than verified confirmation from Anthropic. It's also worth reviewing which folders have been granted to Claude during past agent sessions, since the flaw specifically targeted those approved folders rather than the whole disk.
TechCrunch also ties Apple's broader policy shift to a Wired report describing a separate flaw in ChatGPT's Mac app that could have exposed sensitive data. TechCrunch's report doesn't detail how that flaw worked or confirm whether it's been fixed.
Checking Full Disk Access, Automation, and app-level grants
Reviewing exposure doesn't require waiting for Apple's update. Open System Settings → Privacy & Security → Full Disk Access to see which apps currently hold the permission, according to Lapcat Software's analysis.
That list isn't the whole picture. Older, independently documented macOS research from SentinelOne found that the Finder always has Full Disk Access and never appears in that pane, and any app allowed to control the Finder through the separate Automation settings effectively inherits that same access without showing up on the Full Disk Access screen, according to SentinelOne's research. That Automation consent is typically a one-time click-through and stays in force until manually revoked, so check Privacy & Security → Automation separately.
Terminal deserves its own look too. A 2022 analysis by developer Jeff Johnson, unrelated to Apple's current announcement, found that granting Full Disk Access to Terminal effectively extends that access to every unsandboxed app on the Mac, since those apps can open and run shell scripts through Terminal, which then execute with Terminal's own permissions rather than the calling app's, per Lapcat Software.
Per-folder grants, like the folders a user selects inside Claude Desktop, and connector toggles, like the Messages setting inside Muse, may be managed inside the app itself rather than in a system settings pane. Checking macOS's Full Disk Access and Automation lists won't surface those; Apple's announced permission change hasn't been described as a fix for these app-specific settings, so they need to be reviewed app by app.
That leaves three practical groups:
- Anyone who hasn't granted an AI app broad Mac access has nothing urgent to undo, but should treat any future Full Disk Access prompt as a deliberate decision rather than a quick click past a dialog.
- Anyone with existing Full Disk Access, Automation, or per-folder grants should open both System Settings panes and revoke anything no longer needed.
- Anyone running Muse, Claude Desktop, or ChatGPT's Mac app should check that app's own connector or folder settings directly, since none of these cases were addressed by a change at the macOS level.
What to do with your Mac right now
Nothing about Apple's new approval step has shipped, so there's no setting to flip or update to install yet. In the meantime:
- Open System Settings → Privacy & Security → Full Disk Access and remove any app that no longer needs the permission.
- Check Automation under the same pane, since apps with Finder control can hold full-disk-level access without appearing in the Full Disk Access list.
- If running Claude Desktop, check whether the version is 1.1.2321 or later, per the researcher's disclosure, and review which folders have been granted access.
- If running Muse or a similar AI agent, check its Messages or file connector setting inside the app itself, not just macOS permissions.
- Hold off granting Full Disk Access to unlock a convenience feature until Apple publishes details of its new approval step.
Comments
Be the first, drop a comment!